CVE-2016-7955: Critical severity alienvault open source security information management vulnerability
The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote attackers to bypass authentication and consequently obtain sensitive information, modify the application, or execute arbitrary code as root via an "AV Report Scheduler" HTTP User-Agent header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7955?
CVE-2016-7955 is rated as a critical severity vulnerability due to its potential to allow remote attackers to bypass authentication and execute arbitrary code.
How do I fix CVE-2016-7955?
To fix CVE-2016-7955, upgrade AlienVault OSSIM or Unified Security Management to version 5.3.1 or later.
What systems are affected by CVE-2016-7955?
CVE-2016-7955 affects AlienVault OSSIM versions prior to 5.3.1 and AlienVault Unified Security Management versions prior to 5.3.1.
What type of attacks can be executed due to CVE-2016-7955?
CVE-2016-7955 allows attackers to obtain sensitive information, modify the application, or execute arbitrary code as root.
Is CVE-2016-7955 being actively exploited?
While there is no specific public information about active exploitation of CVE-2016-7955, it is critical to apply patches promptly to mitigate risks.